Junglewise Threat Intelligence

CVE-2025-69369: Axiomthemes Racquet Local File Inclusion in WordPress theme

CVE-2025-69369 · Severity: high · CVSS 8.1 · Published 2026-06-02

Vendors: Axiomthemes.

Executive brief

The Racquet theme for WordPress contains a security flaw that allows unauthorized individuals to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view configuration files containing database credentials, potentially leading to a full takeover of the website and its data. This issue is particularly serious as it can be targeted in automated mass-exploitation campaigns.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Axiomthemes Racquet theme (versions up to and including 1.12.0) due to insufficient validation of user-supplied input used in PHP include or require statements (CWE-98). An unauthenticated remote attacker can exploit this by submitting specially crafted requests to include local files from the server's filesystem. Successful exploitation can result in the disclosure of sensitive information, such as the wp-config.php file, or potentially remote code execution if the attacker can upload or manipulate local files. As of the advisory date, no official patch has been released, and users are advised to use third-party mitigation rules.

Affected products

  • Axiomthemes Racquet through 1.12.0

Timeline

  • 2025-08-19: other: Vulnerability reported by security researcher
  • 2026-01-07: advisory: Patchstack published initial advisory details
  • 2026-06-02: disclosed: CVE published to NVD

References